Skip to main content
Zemerc
RMSProtect · Safety, Risk & Assurance

Risk Management System

One governed enterprise risk register, one approved methodology and one audit trail.

The controlled record of an organisation’s enterprise risk: a register with a ten-state lifecycle, assessment against the organisation’s own matrices with a multidimensional consequence model, facilitated workshops at four depths, a control register that keeps design effectiveness apart from operating effectiveness, and reports frozen at the moment they are issued.

0
Lifecycle states
0
Workshop depths
0
Organisation levels
0
Loadable datasets
Two ways a register lies

Unrated is not low. Untested is not effective.

RMS does not treat unassessed risks as low or untested controls as effective. Unrated risks and controls without effectiveness evidence remain explicitly visible so the reported position reflects the register that actually exists.

Unrated risks stay visible

A risk with no approved assessment is shown as unrated and drawn in the exposure bar rather than excluded from it. The distribution then describes the register that exists, not the subset somebody got round to scoring.

Control assurance is separate from control count

Not working, working but not as designed, never assessed and open deficiencies are four different positions. A control register that reports only how many controls exist is reporting nothing.

The register

Current and residual rating, and a dash where there is neither.

One register covers strategic, corporate, project, operational, engineering, financial, compliance, sustainability and cyber risk under a common approved methodology, with each risk carrying its own review date and current governance state.

RMS risk register showing enterprise risks across their lifecycle, including current and residual ratings, next review dates and explicit identification of risks that have no approved assessment rather than treating them as low or excluding them.

Where a risk has no approved assessment the rating columns show a dash, because a blank and a low score are not the same statement.

  • One methodology
    Every rating on the register comes from the same configurable matrix, so a rating means the same thing in a workshop and on the board pack.
  • Consequence is multidimensional
    Safety, environment, financial, reputational and other dimensions are assessed separately rather than collapsed into one judgement.
  • Review is a date, not an intention
    Overdue reviews are reported as a share of the register, because a register nobody reviews stops being a control.
The lifecycle

A rating arrives when an assessment is approved.

Not when it is drafted, and not when somebody suggests one in a workshop. Until approval the risk counts on the register and carries no rating, which is exactly the uncomfortable state most registers are designed to hide.

Risk
Draft
Identified
Under assessment
Approved
Active
Closed
Returned to owner
Controls

A control is only a control if something has tested it.

The barrier model makes the question concrete: which controls stand between a cause and the event, which stand between the event and its consequences, and what evidence exists that each of them works.

Equipment failure
Process deviation
Third-party action
Human factor
Safety
Environment
Financial
Reputation
Design
Procedure
Monitoring
Competence
Detection
Mitigation
Recovery
Top event
  • Unrated is not low

    A risk with no approved assessment is shown as unrated, never as low. It is drawn in the exposure bar rather than left out of it, so the picture describes the register that exists.

  • Design apart from operation

    A control can be well designed and not working, or working but not as designed. RMS records those separately, because collapsing them is how a control register comes to say everything is effective.

  • Frozen at issue

    A report is frozen when it is issued, so a board pack from March still shows what it showed in March even after the register has moved.

  • Corrected by appending

    A record is corrected by appending rather than rewriting, and the audit log is append-only. What the register said at the time of a decision remains recoverable.

Capability architecture

Operations, workshops, controls, knowledge and governance.

The application's own navigation. It runs standalone and does not duplicate what another application already masters. Every chip is a page.

  • Risk operations

    The enterprise register through a ten-state lifecycle, assessed against configurable matrices with a multidimensional consequence model, with treatments, actions and reviews held against each risk.

    • Risk Operations
    • Risk register
    • Assessments
    • Treatments
    • Reviews
  • Workshops

    Follow a governed sequence of preparation, pre-pack, facilitated session, outcomes and review so workshop conclusions enter the enterprise register with their methodology and evidence intact.

    • Workshops
    • Preparation
    • Pre-pack
    • Session
    • Outcomes
  • Controls

    A control register where design effectiveness and operating effectiveness are recorded separately, with barrier models, deficiencies, and key risk, control and performance indicators against thresholds.

    • Controls
    • Control register
    • BowTie
    • Deficiencies
    • Indicators
  • Risk knowledge

    Reusable risk archetypes, a risk breakdown structure and risk packs, so a new project starts from what the organisation already knows about its own risks.

    • Risk Knowledge
    • Archetypes
    • Risk breakdown structure
    • Risk packs
    • Knowledge Library
  • Governance

    Appetite, tolerance and escalation thresholds, enterprise objectives, an eleven-level organisation structure and the calendar that carries the review cycle.

    • Governance
    • Appetite & tolerance
    • Objectives
    • Organisation
    • Calendar
  • Analytics and reporting

    Analytics, enterprise search and reports frozen at issue, with data management and integrations beneath them and an append-only audit log behind every change.

    • Analytics
    • Reports
    • Enterprise Search
    • Data management
    • Integrations
From workshop to board

The workshop conclusion lands in the register.

Facilitated workshops move from preparation through pre-pack, session, outcomes and review, with approved conclusions entered into the register. Issued board reports are retained as dated records so the position reported at a particular time remains reproducible.

  • Reusable archetypes and a risk breakdown structure so a workshop starts from what is known
  • Appetite, tolerance and escalation thresholds set once and applied consistently
  • Reports frozen at issue, and corrections made by appending
Preview before commit

Nothing is written until a preview has been accepted.

Import, bulk update, historical migration, export, templates and extract each state what they do and what they will not do. A historical migration brings dated records from a previous system in at the date they happened, and they cannot be changed afterwards.

  • Twenty-six loadable datasets across every business area
  • Templates carry the organisation’s own allowed values
  • A complete extract of everything the organisation holds
Also in RMS

More of what the application covers.

  • Configurable matrices with a multidimensional consequence model
  • Appetite, tolerance and escalation thresholds
  • Eleven-level organisation structure
  • Risk archetypes and a risk breakdown structure
  • Key risk, control and performance indicators against thresholds
  • Risk 360: assessments, controls, treatments, actions, reviews and timeline
  • Validated import and export with preview before commit
  • Append-only audit log behind every change
RMS

See RMS with one of your board risk registers.

Bring one risk register and one recent workshop. We will show the lifecycle it enters, the control assurance position behind it and the board report it would freeze.